Vulnerabilities > Google > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-07-17 CVE-2020-0224 Type Confusion vulnerability in Google Android
In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion.
network
low complexity
google CWE-843
critical
9.8
2020-07-09 CVE-2020-7692 Incorrect Authorization vulnerability in Google Oauth Client Library for Java
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps.
network
low complexity
google CWE-863
critical
9.1
2020-06-16 CVE-2020-0235 Out-of-bounds Write vulnerability in Google Android
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr".
network
low complexity
google CWE-787
critical
9.8
2020-06-16 CVE-2020-0232 Use After Free vulnerability in Google Android
Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it.
network
low complexity
google CWE-416
critical
9.8
2020-06-16 CVE-2020-0223 Out-of-bounds Write vulnerability in Google Android
This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450
network
low complexity
google CWE-787
critical
9.8
2020-06-11 CVE-2020-0217 Out-of-bounds Write vulnerability in Google Android 10.0
In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
critical
9.8
2020-06-11 CVE-2020-0201 Unspecified vulnerability in Google Android 10.0
In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy.
network
low complexity
google
critical
9.8
2020-06-11 CVE-2020-0138 Out-of-bounds Write vulnerability in Google Android 10.0
In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
critical
9.8
2020-06-10 CVE-2020-0117 Integer Overflow or Wraparound vulnerability in Google Android
In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow.
network
low complexity
google CWE-190
critical
9.8
2020-06-05 CVE-2020-13841 Unspecified vulnerability in Google Android 10.0/9.0
An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets).
network
low complexity
google
critical
9.8